BAA Generator
HomeBAA for Chiropractors
Chiropractic Practices

HIPAA Business Associate Agreement for Chiropractors

By BAA Generator Editorial  ·  Updated Apr 19, 2026  ·  5 min read

Need a BAA right now?

Generate my BAA → See pricing →

Key Takeaways

Direct answer: Yes — chiropractic practices are HIPAA covered entities. As a healthcare provider transmitting PHI electronically, your practice must sign Business Associate Agreements with every vendor that handles patient records: your EHR, billing company, imaging system, and IT support provider. Practice size does not reduce these obligations.

Chiropractic practices often rely on a multi-vendor ecosystem — separate platforms for scheduling, clinical documentation, digital imaging, and billing — and each of those relationships creates a HIPAA BAA requirement. Unlike a solo medical practice that might use a single integrated EHR, chiropractors frequently mix systems from different vendors, making it easy for BAA gaps to appear.

Why Chiropractors Are Covered Entities

Under HIPAA, a covered entity includes healthcare providers who transmit health information electronically in connection with any transaction covered by HIPAA's Transactions Rule. Chiropractic offices that submit insurance claims electronically — directly or through a billing company or clearinghouse — meet this definition.

Covered chiropractic providers include:

A chiropractor who only accepts cash and never submits insurance claims may have an argument that they are not a covered entity — but this is rare, and any practice that uses billing software that submits electronic transactions is almost certainly covered.

What PHI Does a Chiropractic Practice Handle?

PHI in a chiropractic context includes any individually identifiable health information, such as:

Every vendor whose system stores, processes, or transmits any of the above requires a signed BAA before you share that data.

Vendors Chiropractic Practices Typically Need BAAs With

Chiropractic EHR and Practice Management Software

ChiroTouch, Genesis Chiropractic Software, Jane App, ECLIPSE, and Platinum System are among the most widely used platforms. Each of these holds patient clinical records, treatment notes, and billing data. All reputable chiropractic EHR vendors offer BAAs — but you must actively request or execute the agreement. Simply purchasing a subscription does not automatically create a signed BAA.

Billing Companies and Clearinghouses

If your practice uses an outside billing company to submit claims, or a clearinghouse to transmit electronic claims to payers, those companies are business associates. They receive patient names, dates of service, CPT/ICD codes, and insurance IDs — all PHI. Request a BAA before sending the first claim, and retain executed copies in your compliance records.

Digital X-Ray and Imaging Systems

Chiropractic practices routinely take X-rays during initial patient assessments. When digital X-ray systems store images on cloud servers or allow remote access, the software vendor and the cloud infrastructure provider become business associates. Even local PACS (picture archiving and communication systems) may require BAAs if they transmit data outside your office network.

Appointment Scheduling and Patient Recall Platforms

Online scheduling tools and patient recall reminder systems that link a patient's name to your practice name qualify as handling PHI. Platforms like Jane App's scheduling component, Acuity Scheduling (when used with health-related data), or dedicated recall systems all require BAAs.

IT Support and Managed Service Providers

Any IT provider with remote access to your systems — even for routine maintenance — is a business associate if those systems contain patient records. This is one of the most commonly missed BAA requirements in small chiropractic practices. The vendor's claim that they "don't look at" patient data does not change their HIPAA status; their potential access to PHI is what matters.

Cloud Backup and Storage Services

If your patient records are backed up to cloud storage (Google Workspace, Microsoft 365, Dropbox Business, Carbonite), those platforms must have signed BAAs with your practice. Consumer-grade accounts for these services typically do not include BAA provisions — you need a business-tier account with a signed BAA addendum.

The Multi-Vendor Risk in Chiropractic Practices

A distinctive risk for chiropractic offices is the tendency to use separate best-of-breed tools rather than a single integrated platform. When your EHR is one product, your imaging system is a second, your billing is handled by a third-party company, and your IT is managed by a fourth vendor, each relationship requires its own BAA. It is common for practices to have a BAA with their EHR vendor but not with their imaging vendor, billing company, or IT provider.

To close these gaps, conduct a vendor audit: list every external company that can access patient data, and confirm that a signed BAA exists for each one. See our guide on when you need a HIPAA BAA and how to check whether your vendor signs a BAA for a step-by-step approach.

BAA Requirements for Solo Chiropractors

Solo chiropractors sometimes assume that their small practice size creates an exemption or reduced obligation under HIPAA. It does not. HIPAA's BAA requirements under 45 CFR § 164.504(e) apply equally to a one-provider chiropractic office and a twenty-location group practice. The HHS Office for Civil Rights has investigated and fined small healthcare providers — including solo practices — for missing BAAs.

If anything, solo practices face greater risk because they often lack a dedicated compliance officer to track vendor agreements. Building a simple vendor log that records each BAA, the date it was signed, and where the document is stored is a practical way to manage this obligation.

Common Vendor BAA Table for Chiropractors

Vendor Type Example Vendors BAA Required?
Chiropractic EHR / PMChiroTouch, Genesis, Jane App, ECLIPSEYes
Billing companyOutsourced billing firms, ChiroFusion billingYes
ClearinghouseAvaility, Change Healthcare, Office AllyYes
Digital X-ray / imagingCarestream, Konica Minolta, PhilipsYes (if cloud-connected)
IT support / MSPLocal IT provider, remote support firmYes
Cloud backupMicrosoft 365, Google Workspace BusinessYes
Patient schedulingJane App, NexHealth, Acuity (health context)Yes

Generate a compliant BAA in 5 minutes

HHS model BAA provisions · 45 CFR § 164.504(e) compliant · clean PDF + editable Word

No subscription · PDF + Word · Free watermarked preview

Frequently Asked Questions

Do chiropractors need a HIPAA Business Associate Agreement?

Yes. Chiropractic practices are HIPAA covered entities because they are healthcare providers who transmit health information electronically in connection with standard transactions such as insurance claims. Every vendor that creates, receives, maintains, or transmits PHI on behalf of a chiropractic practice must sign a BAA under 45 CFR § 164.504(e).

What software vendors require BAAs for chiropractic practices?

ChiroTouch, Genesis Chiropractic Software, Jane App, ECLIPSE, and Platinum System all provide BAAs. You also need BAAs with your billing company or clearinghouse, your digital imaging vendor (if cloud-connected), your IT support provider, and any cloud backup or patient communication platform you use.

Does a solo chiropractor need HIPAA BAAs?

Yes. HIPAA does not exempt small or solo practices from the BAA requirement. A solo chiropractor using cloud-based practice management software or an outside billing company has the same obligations as a large multi-provider group. The HHS OCR has pursued enforcement actions against solo providers for missing BAAs.

Does a chiropractic imaging system require a BAA?

Yes, if the imaging system stores images in the cloud or allows remote access and those images can be linked to identifiable patients. Most modern digital X-ray and CBCT vendors with cloud storage components offer BAAs. Contact your imaging vendor's compliance team to request one if you haven't already signed one.

Frequently Asked Questions

Do chiropractors need a HIPAA Business Associate Agreement?
Yes — chiropractic practices are HIPAA covered entities because they are healthcare providers who transmit health information electronically in connection with standard HIPAA transactions (such as insurance claims). This means they must execute Business Associate Agreements with every vendor that creates, receives, maintains, or transmits protected health information on their behalf, under 45 CFR § 164.504(e).
What software vendors require BAAs for chiropractic practices?
Chiropractic practices typically need BAAs with: chiropractic EHR and practice management software (ChiroTouch, Genesis Chiropractic Software, Jane App, ECLIPSE, Platinum System), medical billing companies and clearinghouses, X-ray and digital imaging storage vendors, patient scheduling and recall platforms, IT managed service providers with remote system access, and cloud backup or document storage services that contain patient records.
Does a solo chiropractor need HIPAA BAAs?
Yes. HIPAA does not provide an exemption based on practice size. A solo chiropractor using an EHR, an outside billing company, or a cloud-based scheduling platform has the same BAA obligations as a large multi-provider practice. The HHS Office for Civil Rights has pursued enforcement actions against small healthcare providers — including solo practices — for missing BAAs.
Does a chiropractic imaging system require a BAA?
Yes, if the imaging system stores or transmits images in a way that links them to identifiable patient records. Digital X-ray and CBCT systems that upload images to cloud storage or allow remote access require BAAs with both the software vendor and the cloud storage provider. On-premise systems that never transmit data outside your network may not require a vendor BAA, but you should verify with your vendor's compliance team.

Vendor BAA guides for this specialty

SimplePractice Google Workspace Jotform Acuity